4.3
CVSSv2

CVE-2011-0167

Published: 11/03/2011 Updated: 31/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The windows functionality in WebKit in Apple Safari prior to 5.0.4 allows remote malicious users to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 2.0

apple safari 2.0.1

apple safari 2.0.3

apple safari 1.2.3

apple safari 1.3.1

apple safari 1.2.1

apple safari 1.2

apple safari 1.0.0b1

apple safari 1.0.0b2

apple safari 3.0

apple webkit

apple safari 3.0.3

apple safari 3.1.2

apple safari 3.2.0

apple safari 1.1

apple safari 4.1

apple safari 1.3.2

apple safari 2.0.2

apple safari 1.0.3

apple safari 4.1.2

apple safari 1.0.0

apple safari 3.0.0b

apple safari 3

apple safari 3.0.4

apple safari 3.0.2

apple safari 3.0.4b

apple safari 3.0.1b

apple safari 3.1.0b

apple safari 1.3.0

apple safari 1.2.4

apple safari 1.2.0

apple safari 1.1.1

apple safari 1.0.2

apple safari 1.1.0

apple safari 1.0

apple safari 1.0.1

apple safari 1.3

apple safari 2.0.4

apple safari 5.0

apple safari 3.1.0

apple safari 3.1.1

apple safari 2.0.0

apple safari 3.2.1

apple safari 2

apple safari 1.2.2

apple safari 1.2.5

apple safari 5.0.1

apple safari 3.0.0

apple safari 3.0.1

apple safari 3.0.3b

apple safari 3.0.2b

apple safari 3.2.2

apple safari 5.0.2

apple safari 4.1.1

apple safari

Exploits

source: wwwsecurityfocuscom/bid/46816/info WebKit is prone to a cross-domain scripting vulnerability because it fails to properly enforce the same-origin policy Successfully exploiting this issue will allow attackers to send the content of arbitrary files from the user's system to a remote server controlled by them This results in disc ...